Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)Help Net Security·Dec 4, 00:00 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
Developers scramble as critical React flaw threatens major appsCyberScoop·Dec 3, 19:23 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-6647860
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
New React RSC Vulnerabilities Enable DoS and Source Code ExposureThe Hacker News·Dec 12, 18:36 UTC · Dec 12, 2025VulnerabilityCVE-2025-55182CVE-2025-55184CVE-2025-67779+1 CVEs60
Critical React Native CLI Flaw Exposed Millions of Developers to Remote AttacksThe Hacker News·Nov 4, 14:24 UTC · Nov 4, 2025VulnerabilityCVE-2025-1195360
Why React Didn't Kill XSS: The New JavaScript Injection PlaybookThe Hacker News·Jul 29, 10:00 UTC · Jul 29, 2025Vulnerability55
Federal agencies now only have one more day to patch React2Shell bugThe Record·Dec 11, 19:54 UTC · Dec 11, 2025Vulnerability in the wildCVE-2025-5518260
Admins and defenders gird themselves against maximumArs Technica · Security·Dec 3, 23:16 UTC · Dec 3, 2025VulnerabilityCVE-2025-55182CVE-2025-6647847
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm PackageThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-11953160
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.The Hacker News·Jun 2, 11:58 UTC · Jun 2, 2026Vulnerability in the wild60
Vulnerability landscape in Q4 2025Kaspersky Securelist·Mar 6, 10:00 UTC · Mar 6, 2026Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+7 CVEs160
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell VulnerabilityThe Hacker News·Dec 5, 16:12 UTC · Dec 5, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-31324CVE-2025-133860
North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm PackagesThe Hacker News·Jun 25, 09:20 UTC · Jun 25, 2025Vulnerability42
Over 70 Malicious npm and VS Code Packages Found Stealing Data and CryptoThe Hacker News·May 26, 15:12 UTC · May 26, 2025Vulnerability55
Beyond Vulnerability ManagementThe Hacker News·May 9, 16:51 UTC · May 9, 2025Vulnerability in the wild60
Attackers can bypass middleware auth checks by exploiting critical Next.js flawSecurity Affairs·Mar 24, 11:22 UTC · Mar 24, 2025VulnerabilityCVE-2025-2992760
Webinar: Learn How ASPM Transforms Application Security from Reactive to ProactiveThe Hacker News·Mar 7, 11:35 UTC · Mar 7, 2025Vulnerability30
Contrast Scan empowers developers to analyze front-end code for vulnerabilitiesHelp Net Security·Oct 6, 00:00 UTC · Oct 6, 2022Vulnerability30
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacksCyberScoop·Feb 25, 13:30 UTC · Feb 25, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack OverflowThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026VulnerabilityCVE-2025-59466CVE-2025-55131CVE-2025-55130+1 CVEs60
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60
GreyNoise enhances threat response with real-time blocklists, feeds, and SOAR integrationsHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2025Vulnerability in the wild60
CTEM is the New SOC: Shifting from Monitoring Alerts to Measuring RiskThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Vulnerability55
Applying the Tyson Principle to Cybersecurity: Why Attack Simulation is Key to Avoiding a KOThe Hacker News·Jan 12, 13:43 UTC · Jan 12, 2024Vulnerability55
What you need before the next vulnerability hitsHelp Net Security·Mar 28, 00:00 UTC · Mar 28, 2023Vulnerability55
Thousands of npm accounts use email addresses with expired domainsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability42
UK and US share more vulnerabilities exploited by Russia's APT29 hackersThe Record·Dec 9, 00:00 UTC · Dec 9, 2022Vulnerability in the wildCVE-2018-13379CVE-2019-1653CVE-2019-2725+9 CVEs60
Expert discloses new iPhone lock screen vulnerability in iOS 15Security Affairs·Sep 29, 18:50 UTC · Sep 29, 2021VulnerabilityCVE-2021-1835CVE-2021-3069935
Friday Squid Blogging: Striped Pyjama SquidSchneier on Security·Jan 27, 14:14 UTC · Jan 27, 2020Vulnerability130
Data-driven vehicles: The next security challengeHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2020Vulnerability30
CISO priorities: Implementing security from the get-goHelp Net Security·Aug 30, 00:00 UTC · Aug 30, 2019Vulnerability30
Research shows Tesla Model 3 and Model S are vulnerable to GPS spoofing attacksHelp Net Security·Jun 24, 11:25 UTC · Jun 24, 2019Vulnerability55
Building a strong cybersecurity program for the long haulHelp Net Security·Jun 12, 00:00 UTC · Jun 12, 2017Vulnerability55
Security holes in corporate networks: network vulnerabilitiesKaspersky Securelist·Nov 7, 08:52 UTC · Nov 7, 2014Vulnerability55
Kaspersky Lab report: Evaluating the threat level of software vulnerabilitiesKaspersky Securelist·Feb 1, 14:30 UTC · Feb 1, 2013Vulnerability in the wild160